How Praxiko handles your data
Praxiko runs on regional cloud infrastructure with privacy-by-default settings. Today, Praxiko's database is hosted in Australia, in the Sydney region. A small number of supporting services operate from outside Australia — email delivery among them — and our privacy policy names each one that handles information on our behalf. Praxiko is built to be region-native: our aim is that as a market gains its own cloud region, that market's records are held in-region; until a market has its own region, its records are held in Australia. The trust signals below are factual and mechanical — the practitioner interprets the data; Praxiko keeps the record.
Reasons you can trust us
Your data can't be quietly taken
Why it matters — A breach of a health record is not like a breach of a shopping account. Your clients told you things they haven't told anyone else, and that is what we are protecting.
How we meet it — Every connection to Praxiko is encrypted and can't be downgraded — the browser refuses an insecure one before it is even attempted. Nothing travels in the clear, on any network, including a clinic's shared wi-fi.
Your database stays in Sydney
How we meet it — Praxiko's database — every practitioner and client record it holds — is in Supabase's Sydney region
(ap-southeast-2). The region is fixed when the
project is created, so it isn't a setting that can quietly move the database offshore. Two
things qualify that. Email is one: the provider that delivers Praxiko's emails operates from
outside Australia, so invitations and notifications — and the client names they carry — do
leave the country. No clinical content is ever emailed — no check-in data, no notes, no
tracker history. The other is support access: some of our providers' engineering and support
staff can reach systems from outside Australia. Our privacy policy names every provider that
handles information on our behalf, where it sits, and what it receives — and it describes
the other kinds of connection too.
Even if data were stolen, it would be unreadable
Why it matters — Encryption is the layer that assumes something has already gone wrong. If a copy of the data were ever taken, it would be useless to whoever took it.
How we meet it — Client information is encrypted both while it is stored and while it moves between your device and Praxiko.
Only the right people can get in
Why it matters — Your clients' records are visible to your practice and to nobody else's. Another practice using Praxiko cannot see your clients, and cannot discover that they exist.
How we meet it — Every request is checked against the practice it belongs to, in the database itself rather than in the app. A request for another practice's data returns nothing, because there is nothing there to return.
Runs under your practice's name
How we meet it — Each practice's clients see their clinic, co-branded with Praxiko. Data is scoped and labelled to the clinic at the database level — one practice's records are never visible to another.
Stores and surfaces; doesn't interpret
How we meet it — Praxiko stores and surfaces clinical information. It doesn't score symptoms, generate treatment recommendations, or auto-flag check-in answers. The practitioner interprets; the software keeps the record. That line is deliberate — it keeps Praxiko on the right side of medical-device regulation, and it keeps the clinical judgement where it belongs. Australia is the current launch market; the AHPRA advertising guidelines shape what Praxiko publishes about regulated health services here, and equivalent regimes apply in other English-language jurisdictions.